# NVD CVE Vulnerability Search (`maximedupre/nvd-cve`) Actor

Search the NIST National Vulnerability Database for a keyword or exact CVE ID. Filter by CVSS severity, publication or modification dates, and an affected CPE name, then save structured CVE details with CVSS, CWE, product, reference, and optional CISA KEV data.

- **URL**: https://apify.com/maximedupre/nvd-cve.md
- **Developed by:** [Maxime Dupré](https://apify.com/maximedupre) (community)
- **Categories:** Developer tools, Automation, Business
- **Stats:** 2 total users, 1 monthly users, 100.0% runs succeeded, 0 bookmarks
- **User rating**: No ratings yet

## Pricing

$0.35 / 1,000 cves

This Actor is paid per event. You are not charged for the Apify platform usage, but only a fixed price for specific events.

Learn more: https://docs.apify.com/actors/running/actors-in-store.md#pay-per-event

## What's an Apify Actor?

An Actor is a serverless cloud program that runs on the Apify platform. It has two run modes.
In Batch mode, an Actor accepts a well-defined JSON input, performs an action which can take anything from a few seconds to a few hours,
and optionally produces a well-defined JSON output, datasets with results, or files in key-value store.
In Standby mode, an Actor provides a web server which can be used as a website, API, or an MCP server.

Apify vocabulary and the platform model are defined once, in the agent quickstart at https://apify.com/agents.md.

## How to integrate an Actor?

If asked about integration, you help developers integrate Actors into their projects.
You adapt to their stack and deliver integrations that are safe, well-documented, and production-ready.

Do not guess an integration path. Every one of them is in the agent quickstart at https://apify.com/agents.md: the Apify MCP server, Agent Skills with the Apify CLI, the JavaScript and Python clients, the REST API, and the account-free path for an agent with no human to sign in. It also carries the rule on stating cost before the first paid run.

For examples already wired to this Actor's own input schema, see the [API](#api) section below.

Each client library has reference documentation the quickstart does not restate: [JavaScript/TypeScript](https://docs.apify.com/api/client/js/docs.md) (`npm install apify-client`) and [Python](https://docs.apify.com/api/client/python/docs.md) (`pip install apify-client`).

# README

### 🔎 Find the CVEs behind a vulnerability keyword

Security teams, developers, and researchers can search the NIST National Vulnerability Database by keyword or exact CVE ID. Each saved dataset row keeps source-backed CVE details, CVSS metrics, CWE weaknesses, affected product matches, references, and optional CISA KEV context. Use those fields for vulnerability review, software checks, or security reports. No NVD credential is needed for the public catalog search.

- Search the **[National Vulnerability Database](https://apify.com/maximedupre/nvd-cve/examples/national-vulnerability-database)** for CVEs tied to a vulnerability keyword.
- Build a **[CVE list](https://apify.com/maximedupre/nvd-cve/examples/cve-list)** for a broader set of matching records.
- Open **[CVE details](https://apify.com/maximedupre/nvd-cve/examples/cve-details)** for one exact vulnerability ID.
- Narrow a software lookup with a **[CPE search](https://apify.com/maximedupre/nvd-cve/examples/cpe-search)**.
- Look up **[Common Vulnerabilities and Exposures](https://apify.com/maximedupre/nvd-cve/examples/common-vulnerabilities-and-exposures)** records from the NVD catalog.
- Start an **[NVD search](https://apify.com/maximedupre/nvd-cve/examples/nvd-search)** with a keyword, severity, or date filter.

#### 📦 CVE records with security context

Each saved row represents one CVE returned by the NVD. It includes the CVE identifier, English description, NVD status, publication and last-modified timestamps, source identifier, the selected CVSS assessment, CWE weaknesses, affected product matches, reference links, and CISA KEV context when available.

The `cvss.version` field identifies the selected assessment as CVSS 2.0, 3.0, 3.1, or 4.0. Version-specific metric fields appear when the NVD assessment supplies them. The optional `cisaKev` object appears when the CVE is listed in the CISA Known Exploited Vulnerabilities catalog.

#### ▶️ Search the NVD catalog in one run

Choose one search mode, add any filters, and start the run. Choose Keyword to search NVD vulnerability descriptions, or choose CVE ID to look up one exact identifier. Severity, publication dates, modification dates, and an affected CPE name can filter either mode. Fields for the inactive mode are ignored, and one run uses one search mode.

The Actor saves one row per CVE. If the same CVE appears again while the source is being read, the first eligible match is saved and later matches are ignored. Open the Dataset tab when the run finishes to review or export the rows.

#### ⚙️ Input

Use `searchBy` to choose a keyword search or an exact CVE ID lookup. Add the matching value, then use the shared filters when needed.

| Field | Type | What it does |
| --- | --- | --- |
| `searchBy` | string | Required. Choose `keyword` or `cveId`. |
| `keyword` | string | When `searchBy` is `keyword`, finds CVEs whose NVD record matches this keyword. |
| `maxItems` | integer | Stops after this many matching CVEs. Leave empty to return all available results until the source is exhausted or the run ends. |
| `cveId` | string | When `searchBy` is `cveId`, retrieves one vulnerability by its exact CVE identifier. |
| `severity` | array of strings | Keeps CVEs in the selected CVSS categories: `LOW`, `MEDIUM`, `HIGH`, or `CRITICAL`. Leave empty to include all categories. |
| `publicationDateRange` | object | Keeps CVEs published in the selected UTC date range. |
| `publicationDateRange.from` | string | First publication date to include, in UTC, using `YYYY-MM-DD`. |
| `publicationDateRange.to` | string | Last publication date to include, in UTC, using `YYYY-MM-DD`. |
| `modificationDateRange` | object | Keeps CVEs last modified in the selected UTC date range. |
| `modificationDateRange.from` | string | First last-modified date to include, in UTC, using `YYYY-MM-DD`. |
| `modificationDateRange.to` | string | Last last-modified date to include, in UTC, using `YYYY-MM-DD`. |
| `cpeName` | string | Keeps CVEs that list this affected software CPE name. |

**Successful beta default-input example**

```json
{
  "searchBy": "keyword",
  "keyword": "log4j",
  "maxItems": 25
}
```

`maxItems` is the Actor Work Limit. Leave it empty when you want all available matching results until the NVD source is exhausted or the run ends.

#### 🧾 Output

**Output link**

| Field | Type | What it does |
| --- | --- | --- |
| `results` | string | Link to the CVE result rows in the dataset. |

All dataset rows use the same top-level shape. The selected CVSS version changes which nested metric fields are present. Optional fields are omitted when the source does not supply them.

**CVE row fields**

| Field | Type | What it does |
| --- | --- | --- |
| `cveId` | string | CVE identifier for the vulnerability. |
| `description` | string | English vulnerability description from NVD. |
| `status` | string | Status recorded by NVD for the CVE. |
| `publishedAt` | string | UTC date and time when NVD published the CVE record. |
| `lastModifiedAt` | string | UTC date and time when NVD last modified the CVE record. |
| `sourceIdentifier` | string | NVD identifier for the organization that supplied or assigned the CVE. |
| `cvss` | object | Selected NVD CVSS assessment. |
| `cvss.version` | string | CVSS version that supplied the assessment: `2.0`, `3.0`, `3.1`, or `4.0`. |
| `cvss.score` | number | CVSS base score. |
| `cvss.severity` | string | CVSS severity category. |
| `cvss.vector` | string | CVSS vector string. |
| `cvss.attackVector` | string | CVSS attack vector, when supplied. |
| `cvss.attackComplexity` | string | CVSS attack complexity, when supplied. |
| `cvss.attackRequirements` | string | CVSS 4.0 attack requirements, when supplied. |
| `cvss.privilegesRequired` | string | Privileges required by the CVSS attack, when supplied. |
| `cvss.userInteraction` | string | User interaction required by the CVSS attack, when supplied. |
| `cvss.scope` | string | CVSS scope, when supplied. |
| `cvss.confidentiality` | string | CVSS confidentiality impact, when supplied. |
| `cvss.integrity` | string | CVSS integrity impact, when supplied. |
| `cvss.availability` | string | CVSS availability impact, when supplied. |
| `cvss.accessVector` | string | CVSS 2.0 access vector, when supplied. |
| `cvss.accessComplexity` | string | CVSS 2.0 access complexity, when supplied. |
| `cvss.authentication` | string | CVSS 2.0 authentication requirement, when supplied. |
| `cvss.vulnerableSystemConfidentiality` | string | CVSS 4.0 confidentiality impact on the vulnerable system, when supplied. |
| `cvss.vulnerableSystemIntegrity` | string | CVSS 4.0 integrity impact on the vulnerable system, when supplied. |
| `cvss.vulnerableSystemAvailability` | string | CVSS 4.0 availability impact on the vulnerable system, when supplied. |
| `cvss.subsequentSystemConfidentiality` | string | CVSS 4.0 confidentiality impact on a subsequent system, when supplied. |
| `cvss.subsequentSystemIntegrity` | string | CVSS 4.0 integrity impact on a subsequent system, when supplied. |
| `cvss.subsequentSystemAvailability` | string | CVSS 4.0 availability impact on a subsequent system, when supplied. |
| `cvss.exploitabilityScore` | number | CVSS exploitability score, when supplied. |
| `cvss.impactScore` | number | CVSS impact score, when supplied. |
| `weaknesses` | array of objects | CWE weaknesses listed by NVD for the CVE. |
| `weaknesses[].id` | string | CWE identifier. |
| `weaknesses[].name` | string | Human-readable CWE name when NVD provides one. |
| `affectedProducts` | array of objects | Software and version matches listed by NVD. |
| `affectedProducts[].vendor` | string | Vendor from the NVD product identifier. |
| `affectedProducts[].product` | string | Product from the NVD product identifier. |
| `affectedProducts[].version` | string | Product version when specified. |
| `affectedProducts[].versionStartIncluding` | string | First affected version in the range, when supplied. |
| `affectedProducts[].versionStartExcluding` | string | First excluded version before the affected range, when supplied. |
| `affectedProducts[].versionEndIncluding` | string | Last affected version in the range, when supplied. |
| `affectedProducts[].versionEndExcluding` | string | First excluded version after the affected range, when supplied. |
| `affectedProducts[].vulnerable` | boolean | Whether NVD marks this product match as vulnerable. |
| `references` | array of objects | Reference links listed by NVD, such as advisories or patches. |
| `references[].url` | string | Reference URL. |
| `references[].source` | string | Source named by NVD for the reference, when supplied. |
| `references[].tags` | array of strings | Tags describing the reference, when supplied. |
| `cisaKev` | object | CISA Known Exploited Vulnerabilities context when this CVE is listed. |
| `cisaKev.dateAdded` | string | Date CISA added the CVE to its catalog. |
| `cisaKev.dueDate` | string | Action due date listed by CISA. |
| `cisaKev.knownRansomwareCampaignUse` | boolean | Whether CISA marks the CVE as used in known ransomware campaigns. |
| `cisaKev.requiredAction` | string | Action CISA requires for the CVE. |
| `cisaKev.notes` | string | Additional notes from the CISA catalog, when supplied. |

**Genuine CVSS 3.1 row from the current beta build**

```json
{
  "cveId": "CVE-2018-16843",
  "description": "nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive memory consumption. This issue affects nginx compiled with the ngx_http_v2_module (not compiled by default) if the 'http2' option of the 'listen' directive is used in a configuration file.",
  "status": "Modified",
  "publishedAt": "2018-11-07T14:29:00.777Z",
  "lastModifiedAt": "2026-06-17T01:44:53.387Z",
  "sourceIdentifier": "secalert@redhat.com",
  "cvss": {
    "version": "3.1",
    "score": 7.5,
    "severity": "HIGH",
    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
    "attackVector": "NETWORK",
    "attackComplexity": "LOW",
    "privilegesRequired": "NONE",
    "userInteraction": "NONE",
    "scope": "UNCHANGED",
    "confidentiality": "NONE",
    "integrity": "NONE",
    "availability": "HIGH",
    "exploitabilityScore": 3.9,
    "impactScore": 3.6
  },
  "weaknesses": [
    {
      "id": "CWE-400",
      "name": "Uncontrolled Resource Consumption (4.20)"
    }
  ],
  "affectedProducts": [
    {
      "vendor": "f5",
      "product": "nginx",
      "vulnerable": true,
      "versionStartExcluding": "1.9.5",
      "versionEndExcluding": "1.14.1"
    },
    {
      "vendor": "f5",
      "product": "nginx",
      "vulnerable": true,
      "versionStartExcluding": "1.15.0",
      "versionEndExcluding": "1.15.6"
    },
    {
      "vendor": "debian",
      "product": "debian_linux",
      "vulnerable": true,
      "version": "9.0"
    },
    {
      "vendor": "canonical",
      "product": "ubuntu_linux",
      "vulnerable": true,
      "version": "14.04"
    },
    {
      "vendor": "canonical",
      "product": "ubuntu_linux",
      "vulnerable": true,
      "version": "16.04"
    },
    {
      "vendor": "canonical",
      "product": "ubuntu_linux",
      "vulnerable": true,
      "version": "18.04"
    },
    {
      "vendor": "canonical",
      "product": "ubuntu_linux",
      "vulnerable": true,
      "version": "18.10"
    },
    {
      "vendor": "opensuse",
      "product": "leap",
      "vulnerable": true,
      "version": "15.1"
    },
    {
      "vendor": "apple",
      "product": "xcode",
      "vulnerable": true,
      "versionEndExcluding": "13.0"
    }
  ],
  "references": [
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00035.html",
      "source": "secalert@redhat.com",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://mailman.nginx.org/pipermail/nginx-announce/2018/000220.html",
      "source": "secalert@redhat.com",
      "tags": [
        "Mailing List",
        "Vendor Advisory"
      ]
    },
    {
      "url": "http://seclists.org/fulldisclosure/2021/Sep/36",
      "source": "secalert@redhat.com",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://www.securityfocus.com/bid/105868",
      "source": "secalert@redhat.com",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ]
    },
    {
      "url": "http://www.securitytracker.com/id/1042038",
      "source": "secalert@redhat.com",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ]
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2018:3653",
      "source": "secalert@redhat.com",
      "tags": [
        "Third Party Advisory"
      ]
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2018:3680",
      "source": "secalert@redhat.com",
      "tags": [
        "Third Party Advisory"
      ]
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2018:3681",
      "source": "secalert@redhat.com",
      "tags": [
        "Third Party Advisory"
      ]
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16843",
      "source": "secalert@redhat.com",
      "tags": [
        "Issue Tracking",
        "Third Party Advisory"
      ]
    },
    {
      "url": "https://support.apple.com/kb/HT212818",
      "source": "secalert@redhat.com",
      "tags": [
        "Third Party Advisory"
      ]
    },
    {
      "url": "https://usn.ubuntu.com/3812-1/",
      "source": "secalert@redhat.com",
      "tags": [
        "Third Party Advisory"
      ]
    },
    {
      "url": "https://www.debian.org/security/2018/dsa-4335",
      "source": "secalert@redhat.com",
      "tags": [
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00035.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://mailman.nginx.org/pipermail/nginx-announce/2018/000220.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "tags": [
        "Mailing List",
        "Vendor Advisory"
      ]
    },
    {
      "url": "http://seclists.org/fulldisclosure/2021/Sep/36",
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://www.securityfocus.com/bid/105868",
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ]
    },
    {
      "url": "http://www.securitytracker.com/id/1042038",
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ]
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2018:3653",
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "tags": [
        "Third Party Advisory"
      ]
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2018:3680",
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "tags": [
        "Third Party Advisory"
      ]
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2018:3681",
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "tags": [
        "Third Party Advisory"
      ]
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16843",
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "tags": [
        "Issue Tracking",
        "Third Party Advisory"
      ]
    },
    {
      "url": "https://support.apple.com/kb/HT212818",
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "tags": [
        "Third Party Advisory"
      ]
    },
    {
      "url": "https://usn.ubuntu.com/3812-1/",
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "tags": [
        "Third Party Advisory"
      ]
    },
    {
      "url": "https://www.debian.org/security/2018/dsa-4335",
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "tags": [
        "Third Party Advisory"
      ]
    }
  ]
}
```

**Genuine CVSS 2.0 row from the current beta build**

```json
{
  "cveId": "CVE-2013-6450",
  "description": "The DTLS retransmission implementation in OpenSSL 1.0.0 before 1.0.0l and 1.0.1 before 1.0.1f does not properly maintain data structures for digest and encryption contexts, which might allow man-in-the-middle attackers to trigger the use of a different context and cause a denial of service (application crash) by interfering with packet delivery, related to ssl/d1_both.c and ssl/t1_enc.c.",
  "status": "Modified",
  "publishedAt": "2014-01-01T16:05:15.017Z",
  "lastModifiedAt": "2026-06-17T00:00:31.027Z",
  "sourceIdentifier": "secalert@redhat.com",
  "cvss": {
    "version": "2.0",
    "score": 5.8,
    "severity": "MEDIUM",
    "vector": "AV:N/AC:M/Au:N/C:N/I:P/A:P",
    "confidentiality": "NONE",
    "integrity": "PARTIAL",
    "availability": "PARTIAL",
    "accessVector": "NETWORK",
    "accessComplexity": "MEDIUM",
    "authentication": "NONE",
    "exploitabilityScore": 8.6,
    "impactScore": 4.9
  },
  "weaknesses": [
    {
      "id": "CWE-310",
      "name": "CWE CATEGORY: Cryptographic Issues (4.20)"
    }
  ],
  "affectedProducts": [
    {
      "vendor": "openssl",
      "product": "openssl",
      "vulnerable": true,
      "version": "1.0.0"
    },
    {
      "vendor": "openssl",
      "product": "openssl",
      "vulnerable": true,
      "version": "1.0.0a"
    },
    {
      "vendor": "openssl",
      "product": "openssl",
      "vulnerable": true,
      "version": "1.0.0b"
    },
    {
      "vendor": "openssl",
      "product": "openssl",
      "vulnerable": true,
      "version": "1.0.0c"
    },
    {
      "vendor": "openssl",
      "product": "openssl",
      "vulnerable": true,
      "version": "1.0.0d"
    },
    {
      "vendor": "openssl",
      "product": "openssl",
      "vulnerable": true,
      "version": "1.0.0e"
    },
    {
      "vendor": "openssl",
      "product": "openssl",
      "vulnerable": true,
      "version": "1.0.0f"
    },
    {
      "vendor": "openssl",
      "product": "openssl",
      "vulnerable": true,
      "version": "1.0.0g"
    },
    {
      "vendor": "openssl",
      "product": "openssl",
      "vulnerable": true,
      "version": "1.0.0h"
    },
    {
      "vendor": "openssl",
      "product": "openssl",
      "vulnerable": true,
      "version": "1.0.0i"
    },
    {
      "vendor": "openssl",
      "product": "openssl",
      "vulnerable": true,
      "version": "1.0.0j"
    },
    {
      "vendor": "openssl",
      "product": "openssl",
      "vulnerable": true,
      "version": "1.0.1"
    },
    {
      "vendor": "openssl",
      "product": "openssl",
      "vulnerable": true,
      "version": "1.0.1a"
    },
    {
      "vendor": "openssl",
      "product": "openssl",
      "vulnerable": true,
      "version": "1.0.1b"
    },
    {
      "vendor": "openssl",
      "product": "openssl",
      "vulnerable": true,
      "version": "1.0.1c"
    },
    {
      "vendor": "openssl",
      "product": "openssl",
      "vulnerable": true,
      "version": "1.0.1d"
    },
    {
      "vendor": "openssl",
      "product": "openssl",
      "vulnerable": true,
      "version": "1.0.1e"
    }
  ],
  "references": [
    {
      "url": "http://git.openssl.org/gitweb/?p=openssl.git%3Ba=commit%3Bh=34628967f1e65dc8f34e000f0f5518e21afbfc7b",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136470.html",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136473.html",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-updates/2014-01/msg00031.html",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-updates/2014-01/msg00032.html",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://rhn.redhat.com/errata/RHSA-2014-0015.html",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://seclists.org/fulldisclosure/2014/Dec/23",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://security.gentoo.org/glsa/glsa-201412-39.xml",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www-01.ibm.com/support/docview.wss?uid=isg400001841",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www-01.ibm.com/support/docview.wss?uid=isg400001843",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.debian.org/security/2014/dsa-2833",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.openssl.org/news/vulnerabilities.html",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/534161/100/0/threaded",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/64618",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.securitytracker.com/id/1029549",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.securitytracker.com/id/1031594",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.ubuntu.com/usn/USN-2079-1",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.vmware.com/security/advisories/VMSA-2014-0012.html",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://puppet.com/security/cve/cve-2013-6450",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://security-tracker.debian.org/tracker/CVE-2013-6450",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://git.openssl.org/gitweb/?p=openssl.git%3Ba=commit%3Bh=34628967f1e65dc8f34e000f0f5518e21afbfc7b",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136470.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136473.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-updates/2014-01/msg00031.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-updates/2014-01/msg00032.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://rhn.redhat.com/errata/RHSA-2014-0015.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://seclists.org/fulldisclosure/2014/Dec/23",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://security.gentoo.org/glsa/glsa-201412-39.xml",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www-01.ibm.com/support/docview.wss?uid=isg400001841",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www-01.ibm.com/support/docview.wss?uid=isg400001843",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.debian.org/security/2014/dsa-2833",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openssl.org/news/vulnerabilities.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/534161/100/0/threaded",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/64618",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id/1029549",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id/1031594",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.ubuntu.com/usn/USN-2079-1",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vmware.com/security/advisories/VMSA-2014-0012.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://puppet.com/security/cve/cve-2013-6450",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://security-tracker.debian.org/tracker/CVE-2013-6450",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ]
}
```

**Genuine CVSS 4.0 row from the current beta build**

```json
{
  "cveId": "CVE-2025-0168",
  "description": "A vulnerability classified as critical has been found in code-projects Job Recruitment 1.0. This affects an unknown part of the file /_parse/_feedback_system.php. The manipulation of the argument person leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.",
  "status": "Analyzed",
  "publishedAt": "2025-01-01T14:15:23.590Z",
  "lastModifiedAt": "2026-06-17T08:26:00.070Z",
  "sourceIdentifier": "cna@vuldb.com",
  "cvss": {
    "version": "4.0",
    "score": 5.3,
    "severity": "MEDIUM",
    "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
    "attackVector": "NETWORK",
    "attackComplexity": "LOW",
    "attackRequirements": "NONE",
    "privilegesRequired": "LOW",
    "userInteraction": "NONE",
    "vulnerableSystemConfidentiality": "LOW",
    "vulnerableSystemIntegrity": "LOW",
    "vulnerableSystemAvailability": "LOW",
    "subsequentSystemConfidentiality": "NONE",
    "subsequentSystemIntegrity": "NONE",
    "subsequentSystemAvailability": "NONE"
  },
  "weaknesses": [
    {
      "id": "CWE-74",
      "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') (4.20)"
    },
    {
      "id": "CWE-89",
      "name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (4.20)"
    }
  ],
  "affectedProducts": [
    {
      "vendor": "anisha",
      "product": "job_recruitment",
      "vulnerable": true,
      "version": "1.0"
    }
  ],
  "references": [
    {
      "url": "https://code-projects.org/",
      "source": "cna@vuldb.com",
      "tags": [
        "Product"
      ]
    },
    {
      "url": "https://github.com/UnrealdDei/cve/blob/main/sql11.md",
      "source": "cna@vuldb.com",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ]
    },
    {
      "url": "https://vuldb.com/?ctiid.289917",
      "source": "cna@vuldb.com",
      "tags": [
        "Permissions Required",
        "VDB Entry"
      ]
    },
    {
      "url": "https://vuldb.com/?id.289917",
      "source": "cna@vuldb.com",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ]
    },
    {
      "url": "https://vuldb.com/?submit.473107",
      "source": "cna@vuldb.com",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ]
    }
  ]
}
```

**CISA KEV context from a current beta row**

The following genuine row is shortened because its affected product and reference arrays are large. The string value `"..."` marks omitted source data.

```json
{
  "cveId": "CVE-2021-44228",
  "description": "Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.",
  "status": "Analyzed",
  "publishedAt": "2021-12-10T10:15:09.143Z",
  "lastModifiedAt": "2026-08-11T19:33:44.513Z",
  "sourceIdentifier": "security@apache.org",
  "cvss": {
    "version": "3.1",
    "score": 10,
    "severity": "CRITICAL",
    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
    "attackVector": "NETWORK",
    "attackComplexity": "LOW",
    "privilegesRequired": "NONE",
    "userInteraction": "NONE",
    "scope": "CHANGED",
    "confidentiality": "HIGH",
    "integrity": "HIGH",
    "availability": "HIGH",
    "exploitabilityScore": 3.9,
    "impactScore": 6
  },
  "weaknesses": [
    {
      "id": "CWE-20",
      "name": "Improper Input Validation (4.20)"
    },
    {
      "id": "CWE-400",
      "name": "Uncontrolled Resource Consumption (4.20)"
    },
    {
      "id": "CWE-502",
      "name": "Deserialization of Untrusted Data (4.20)"
    },
    {
      "id": "CWE-917",
      "name": "Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') (4.20)"
    }
  ],
  "affectedProducts": "...",
  "references": "...",
  "cisaKev": {
    "dateAdded": "2021-12-10",
    "dueDate": "2021-12-24",
    "knownRansomwareCampaignUse": true,
    "requiredAction": "For all affected software assets for which updates exist, the only acceptable remediation actions are: 1) Apply updates; OR 2) remove affected assets from agency networks. Temporary mitigations using one of the measures provided at https://www.cisa.gov/uscert/ed-22-02-apache-log4j-recommended-mitigation-measures are only acceptable until updates are available.",
    "notes": "https://nvd.nist.gov/vuln/detail/CVE-2021-44228"
  }
}
```

#### 💳 Pricing

Pricing is pay per event. You are charged $0.00035 for each CVE successfully saved to the dataset. A run with no saved CVEs has no CVE event to charge.

#### 🔌 Integrations

https://www.youtube.com/watch?v=bNACk1\_S\_6w\&list=PLObrtcm1Kw6MUrlLNDbK9QRg8VDJg0gOW\&index=4

Use the dataset in JSON, CSV, or Excel, or read it through the Apify API. You can also connect runs to webhooks and scheduled workflows using Apify.

#### ❓ FAQ

##### What happens if I enter a CVE ID and a keyword?

Choose the search mode in `searchBy`. The field for the inactive mode is ignored, so use `keyword` with `searchBy: "keyword"` or `cveId` with `searchBy: "cveId"`.

##### What does an empty maxItems value do?

Leave `maxItems` empty to return all available matching results until the NVD source is exhausted or the run ends. Set it when you want a smaller work limit.

##### Does every CVE include CVSS 4.0 data?

No. The row shows the selected NVD assessment and its `cvss.version`. The available metric fields depend on the CVSS version and the data supplied by NVD.

##### Will the output show affected software versions?

When NVD lists affected product matches, `affectedProducts` can include the vendor, product, version, and version range bounds. It does not expose the full CPE applicability tree.

##### Does every CVE have CISA KEV data?

No. The optional `cisaKev` object appears when the CVE is listed in the CISA Known Exploited Vulnerabilities catalog.

##### Do I need an NVD API key?

No. This Actor searches the public NVD catalog without a customer source credential.

##### Does this test my systems or assess my asset inventory?

No. It returns public CVE data. It does not test live targets, verify exploitability, assess installed versions, or make remediation decisions.

##### Why might a run return no rows?

Your keyword, CVE ID, severity, date, and CPE filters may match no source records. A dataset row is saved only for a matching CVE.

##### Can I use this for a complete CVE database export?

Use an empty `maxItems` value to continue through all available matching results until the source is exhausted or the run ends. The result is still limited by the source and the run, so this does not promise a complete copy of every NVD record.

### 📝 Changelog

**v0.0** (27-09-2026)

- Initial release.

### 🆘 Support

For issues, questions, or feature requests, [file a ticket](https://console.apify.com/actors/maximedupre~nvd-cve/issues) and I'll fix or implement it in less than 24h 🫡

### 🔗 Related Actors

- [GitHub Security Advisories Scraper](https://apify.com/maximedupre/github-security-advisories-scraper) - Compare CVE records with GitHub advisories and package-level fixed-version context.
- [CISA KEV Scraper](https://apify.com/maximedupre/cisa-kev-scraper) - Add CISA due dates and known ransomware-use context for listed CVEs.
- [NVD CVE Vulnerability Search](https://apify.com/ryanclinton/nvd-cve-vulnerability-search) - Search the NVD API through another detailed CVE search workflow.
- [NVD CVE Vulnerability Crawler](https://apify.com/jungle_synthesizer/nvd-cve-crawler) - Explore a broader NVD crawl for catalog-scale CVE collection.
- [NVD CVE Scraper - Vulnerability Database API](https://apify.com/pink_comic/nvd-cve-vulnerability-database) - Use an API-oriented NVD workflow for DevSecOps and vulnerability research.

**Made with ❤️ by Maxime Dupré**

# Actor input Schema

## `searchBy` (type: `string`):

Choose a keyword search or an exact CVE ID lookup.

## `keyword` (type: `string`):

Find CVEs whose NVD record matches this keyword. Example: log4j.

## `maxItems` (type: `integer`):

Stop after this many matching CVEs. Leave empty to return all available results until the source is exhausted or the run ends.

## `cveId` (type: `string`):

Retrieve one vulnerability by its exact CVE ID. Example: CVE-2021-44228.

## `severity` (type: `array`):

Keep CVEs in any selected CVSS severity category. Leave empty to include all categories.

## `publicationDateRange` (type: `object`):

Keep CVEs published in this UTC date range. Leave either date empty to keep that side open.

## `modificationDateRange` (type: `object`):

Keep CVEs last modified in this UTC date range. Leave either date empty to keep that side open.

## `cpeName` (type: `string`):

Keep CVEs that list this affected software CPE name. Example: cpe:2.3:a:apache:log4j:2.14.1:*:*:*:*:*:*:\*.

## Actor input object example

```json
{
  "searchBy": "keyword",
  "keyword": "log4j",
  "maxItems": 25
}
```

# Actor output Schema

## `results` (type: `string`):

Open the CVE result rows.

# API

You can run this Actor programmatically using our API. Below are code examples in JavaScript, Python, and CLI, as well as the OpenAPI specification and MCP server setup.

## JavaScript example

```javascript
import { ApifyClient } from 'apify-client';

// Initialize the ApifyClient with your Apify API token
// Replace the '<YOUR_API_TOKEN>' with your token
const client = new ApifyClient({
    token: '<YOUR_API_TOKEN>',
});

// Prepare Actor input
const input = {
    "searchBy": "keyword",
    "keyword": "log4j",
    "maxItems": 25
};

// Run the Actor and wait for it to finish
const run = await client.actor("maximedupre/nvd-cve").call(input);

// Fetch and print Actor results from the run's dataset (if any)
console.log('Results from dataset');
console.log(`💾 Check your data here: https://console.apify.com/storage/datasets/${run.defaultDatasetId}`);
const { items } = await client.dataset(run.defaultDatasetId).listItems();
items.forEach((item) => {
    console.dir(item);
});

// 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/js/docs

```

## Python example

```python
from apify_client import ApifyClient

# Initialize the ApifyClient with your Apify API token
# Replace '<YOUR_API_TOKEN>' with your token.
client = ApifyClient("<YOUR_API_TOKEN>")

# Prepare the Actor input
run_input = {
    "searchBy": "keyword",
    "keyword": "log4j",
    "maxItems": 25,
}

# Run the Actor and wait for it to finish
run = client.actor("maximedupre/nvd-cve").call(run_input=run_input)

# Fetch and print Actor results from the run's dataset (if there are any)
print(f"💾 Check your data here: https://console.apify.com/storage/datasets/{run.default_dataset_id}")
for item in client.dataset(run.default_dataset_id).iterate_items():
    print(item)

# 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/python/docs/quick-start

```

## CLI example

```bash
echo '{
  "searchBy": "keyword",
  "keyword": "log4j",
  "maxItems": 25
}' |
apify call maximedupre/nvd-cve --silent --output-dataset

```

## MCP server setup

```json
{
    "mcpServers": {
        "apify": {
            "type": "http",
            "url": "https://mcp.apify.com/?tools=fetch-actor-details,maximedupre/nvd-cve"
        }
    }
}
```

The hosted server signs you in with OAuth on first connect, so no API token belongs in this config. Clients without OAuth support can send an `Authorization: Bearer <APIFY_API_TOKEN>` header instead, using a token from API & Integrations in Apify Console (https://console.apify.com/settings/integrations).

## OpenAPI specification

Download the OpenAPI definition: https://api.apify.com/v2/actors/RD50e5VjZT5p9f4El/builds/rzGg3JMB6oU7APNl6/openapi.json
